All guides

GDPR for Shopify Stores: The Complete 2026 Compliance Guide

A practical, jargon-free GDPR guide for Shopify merchants — what applies to you, what to do in the admin, and the exact policies, cookie banner, and DPA setup you need.

PolicyGenie Editorial·May 2026· 12 min read
Page last updated · May 2026

Who this guide is for

You run a Shopify store. You sell — or might one day sell — to anyone in the European Union or the United Kingdom. That puts you inside the scope of the General Data Protection Regulation (GDPR) and the UK GDPR, regardless of where your business is registered. This guide covers exactly what that means in the Shopify admin, what policies you need, and how to set the whole thing up without paying a lawyer £1,500.

Does GDPR apply to your Shopify store?

GDPR applies if either of these is true:

  1. You offer goods or services to people in the EU/UK (you list prices in EUR or GBP, you ship there, you accept orders from there), OR
  2. You monitor the behavior of EU/UK visitors (you run analytics, retargeting pixels, etc.).

In practice, almost every Shopify store on a custom domain falls under one of these. The country your LLC is registered in doesn't matter.

The five things Shopify merchants must do

GDPR is dense, but for a typical Shopify store it reduces to five practical actions:

  1. Publish a compliant privacy policy that names your specific tools and processors.
  2. Publish a cookie policy and run a cookie consent banner for visitors from the EU/UK.
  3. Sign Shopify's Data Processing Addendum (DPA) and any DPAs from your other apps.
  4. Configure Shopify's customer data request workflow so you can respond to access/deletion requests.
  5. Maintain a basic record of processing activities (a one-page spreadsheet is fine for most stores).

We'll walk through each.

1. Privacy policy

Your policy must name specific processors — generic phrases like "we use third parties" are not compliant. For a typical Shopify store, that means listing at minimum:

  • Shopify itself (hosting, checkout, customer accounts)
  • Your payment processor (Shopify Payments / Stripe / PayPal)
  • Your shipping carriers (USPS, Royal Mail, DHL, etc.)
  • Your email platform (Klaviyo, Mailchimp, Shopify Email)
  • Your analytics tools (Google Analytics 4, Shopify Analytics, Hotjar, etc.)
  • Any review app (Judge.me, Loox, Stamped.io)
  • Any retargeting pixels (Meta, TikTok, Google Ads)

The free Shopify privacy policy generator populates all of these from a checklist. Paste the output into Shopify Admin → Settings → Policies → Privacy policy.

2. Cookie banner and cookie policy

Shopify's built-in Customer Privacy API (free, included in your plan) gives you a basic consent banner. To enable it:

  1. Go to Settings → Customer privacy → Cookie banner.
  2. Choose the regions where the banner is shown (set to EU/UK/EEA/Switzerland at minimum).
  3. Choose "Require consent before non-essential cookies fire" — this is GDPR's standard.
  4. Save.

For most stores this is enough. If you run heavy ad tech or want more granular controls (Necessary / Functional / Analytics / Marketing toggles), a paid app like CookieYes, Cookiebot, or Iubenda is the standard upgrade. They cost roughly $10–25/month and integrate with Shopify's Customer Privacy API automatically.

Your cookie policy (separate document) lists every cookie, who set it, what it does, and how long it lasts. Generators auto-populate this from your installed apps.

3. Sign Shopify's DPA

GDPR Article 28 requires a written contract — a Data Processing Addendum — between you (the controller) and every service that processes personal data on your behalf (the processors). Shopify provides one for free.

To accept it: Shopify Admin → Settings → Legal → Data processing addendum → Review and accept. Takes 60 seconds.

Repeat for every app you've installed that handles customer data: Klaviyo, Mailchimp, Judge.me, Gorgias, Recharge, etc. Most have a self-serve DPA accept flow in their app dashboard. Apps that refuse to sign a DPA should be removed.

4. Customer data request workflow

Under GDPR, anyone in the EU/UK can ask you to:

  • Access the personal data you hold on them
  • Delete it ("right to be forgotten")
  • Correct it
  • Export it (data portability)

You have 30 days to respond.

Shopify makes this nearly automatic. Customers → [customer] → ⋯ → Erase personal data / Request customer data. Shopify runs the request across all installed apps that support the Customer Privacy API and gives you a downloadable export or confirmation of deletion. Set a calendar reminder to check your store's privacy inbox weekly.

For requests that arrive via email instead of through your site, your privacy policy should publish a dedicated email address (e.g., privacy@yourdomain.com) and your response template should reference Shopify's flow above.

5. Records of processing activities (Article 30)

If you have fewer than 250 employees and your processing is "occasional" and doesn't involve sensitive data, you may be exempt — but the safest path for any active store is to keep a one-page record. It should list, per processing activity:

  • The purpose (e.g., "Order fulfilment")
  • Categories of data subjects (e.g., "Customers in the EU and UK")
  • Categories of data (e.g., "Name, address, email, order history")
  • Categories of recipients (e.g., "Shopify, payment processor, carrier")
  • Retention period (e.g., "7 years for tax records")
  • Security measures (e.g., "Encryption in transit and at rest via Shopify")

A simple spreadsheet covers this. Update annually.

The cookie banner mistake almost every store makes

Pre-ticked checkboxes are not valid consent under GDPR. If your cookie banner has "Accept all" pre-checked, or fires analytics before the user clicks anything, you're non-compliant. Use Shopify's Customer Privacy API or a banner app that blocks scripts until consent is given — not one that just shows a notice.

This is the single most common reason small stores get reported to data protection authorities. Get it right and you eliminate the vast majority of GDPR risk.

What about transferring data to the US?

Shopify is a Canadian company with US data infrastructure. After the Schrems II ruling, EU→US data transfers require Standard Contractual Clauses (SCCs). The Shopify DPA includes SCCs by default — you're covered just by accepting it.

The same applies to most major SaaS tools (Stripe, Mailchimp, Klaviyo, Google). If you use a niche tool, check that their DPA includes SCCs or the EU-US Data Privacy Framework certification.

Fines and enforcement: how worried should you be?

For a small store, regulators almost never go from zero to fine. The realistic enforcement sequence is:

  1. A user files a complaint with their country's data protection authority.
  2. The authority writes to you asking for your policy, your DPA, and your records of processing.
  3. You have a deadline (typically 30 days) to respond.
  4. If you can't produce them, you get a warning. If you ignore the warning, you get a fine.

So your real defensive posture is: have the documents ready, set up the Shopify customer privacy flow, and respond promptly. That alone covers most realistic risk.

Your 30-minute GDPR setup checklist

  • Accept Shopify's DPA in Settings → Legal
  • Enable the Customer Privacy API cookie banner for EU/UK
  • Generate and publish a Shopify-specific privacy policy
  • Generate and publish a cookie policy
  • List a privacy@yourdomain.com contact email
  • Set a 7-day check-in for the privacy inbox
  • Accept DPAs from every installed app
  • Save a one-page record of processing activities
  • Diary 12-month policy review

Thirty minutes of admin saves you weeks of stress if a regulator (or, more likely, an angry customer) ever asks.

Not legal advice. PolicyGenie is a self-help document tool, not a law firm. The templates and articles here are general information only and may not fit your circumstances or reflect the most recent changes in the law. Review anything you publish, and get advice from a qualified lawyer in your jurisdiction if your business handles sensitive data or operates in a regulated industry. See our full disclaimer.

Get the next guide in your inbox

One compliance deep-dive per month. No spam, ever.

Compliance updates, monthly.

One email a month. No spam. Unsubscribe anytime.